From 4501a7e330c764caaec3a908c2e0afb72a994969 Mon Sep 17 00:00:00 2001 From: Alexandre <44178713+alexbelgium@users.noreply.github.com> Date: Wed, 30 Sep 2026 13:27:54 +0200 Subject: [PATCH] birdnet-go-dev: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH option (#3096) * birdnet-go: restrict ingress to the Supervisor; add INGRESS_SKIP_AUTH (dev) The ingress nginx server in both birdnet-go add-ons listened on the add-on's hassio-network address with no source restriction, so any other add-on container could reach it directly (verified: HTTP 200 from another add-on). Allow only the Supervisor's ingress proxy (172.30.32.2), as Home Assistant requires and as calibre_web already does. birdnet-go-dev gains an INGRESS_SKIP_AUTH option (default false). It is exported as an env var by 00-global_var.sh and read by the fork (alexbelgium/birdnet-go#80) to skip BirdNET-Go's own login for ingress requests only. Co-Authored-By: Claude Opus 5.5 * birdnet-go: drop stable add-on changes; keep this PR to birdnet-go-dev Co-Authored-By: Claude Opus 5.5 --------- Co-authored-by: BirdNET-Go Addon Builder Co-authored-by: Claude Opus 5.5 --- birdnet-go-dev/CHANGELOG.md | 3 +++ birdnet-go-dev/README.md | 9 +++++++++ birdnet-go-dev/config.yaml | 4 +++- birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf | 4 ++++ 4 files changed, 19 insertions(+), 1 deletion(-) diff --git a/birdnet-go-dev/CHANGELOG.md b/birdnet-go-dev/CHANGELOG.md index 15760dbbab..c814a41799 100644 --- a/birdnet-go-dev/CHANGELOG.md +++ b/birdnet-go-dev/CHANGELOG.md @@ -1,3 +1,6 @@ +## 20260929.1 (30-09-2026) +- New `INGRESS_SKIP_AUTH` option (default `false`): when `true`, BirdNET-Go no longer asks for its own login when opened through the Home Assistant sidebar (ingress), since Home Assistant has already signed you in. Direct access on port 8080 still requires the login. +- Security: the ingress web server now only accepts connections from the Home Assistant Supervisor, as Home Assistant requires. ## 20260929 (29-09-2026) - Synced with upstream; merged open PRs (conflicts in #62, #63, #79 resolved) ## 20260920.2 (19-09-2026) diff --git a/birdnet-go-dev/README.md b/birdnet-go-dev/README.md index f00f20920d..4ad3151537 100644 --- a/birdnet-go-dev/README.md +++ b/birdnet-go-dev/README.md @@ -57,6 +57,7 @@ env_vars: [] # extra environment variables to pass to the container TZ: Etc/UTC # timezone, see https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List mqtt_auto_config: false # set true to auto-wire the Home Assistant MQTT addon into config.yaml mariadb_auto_config: false # set true to auto-wire the Home Assistant MariaDB addon into config.yaml (also disables SQLite) +INGRESS_SKIP_AUTH: false # set true to skip the BirdNET-Go login when opened through the Home Assistant sidebar (ingress) ``` - Config.yaml @@ -97,6 +98,14 @@ In practice it only bites when a single audio source has two or more bird models Requires [alexbelgium/birdnet-go#63](https://github.com/alexbelgium/birdnet-go/pull/63). +#### Skip login through ingress + +With `INGRESS_SKIP_AUTH: true`, BirdNET-Go does not show its own login page when you open it from the Home Assistant sidebar (ingress), because Home Assistant has already signed you in. Access on port 8080, and API access, still require the BirdNET-Go login as before. + +**Off by default.** Every Home Assistant user who can open the add-on panel, including non-administrators, then gets full access to BirdNET-Go, settings included. Changing the option requires an add-on restart. + +Requires [alexbelgium/birdnet-go#80](https://github.com/alexbelgium/birdnet-go/pull/80). + ### MQTT and MariaDB auto-configuration (opt-in) If the Home Assistant **MQTT** addon is installed and running and you set `mqtt_auto_config: true` in the addon options, the addon writes the HA Mosquitto credentials directly into BirdNET-Go's `config.yaml` on every startup: `realtime.mqtt.enabled`, `broker`, `username`, and `password` are populated, and the topic defaults to `birdnet`. In addition, it enables BirdNET-Go's **native Home Assistant MQTT auto-discovery** (`realtime.mqtt.homeassistant.enabled`), so the detection sensors show up in Home Assistant automatically — **no manual MQTT sensor YAML required** (the hand-written sensors in [HAINTEGRATION.md](./HAINTEGRATION.md) remain available if you prefer to build your own). Messages are also retained (`realtime.mqtt.retain: true`) so sensor states survive Home Assistant restarts. When the option is `false` (the default), the addon still logs the broker details and reminds you about the option whenever Mosquitto is detected — nothing is written. diff --git a/birdnet-go-dev/config.yaml b/birdnet-go-dev/config.yaml index f03c4a8638..6971f81d13 100644 --- a/birdnet-go-dev/config.yaml +++ b/birdnet-go-dev/config.yaml @@ -92,6 +92,7 @@ options: homeassistant_microphone: false mqtt_auto_config: false mariadb_auto_config: false + INGRESS_SKIP_AUTH: false panel_admin: false panel_icon: mdi:bird ports: @@ -110,6 +111,7 @@ schema: value: str? BIRDSONGS_FOLDER: str? LOG_MAX_SIZE_MB: int(1,1000)? + INGRESS_SKIP_AUTH: bool? LOG_MAX_AGE_DAYS: int(1,365)? TZ: str? cifsdomain: str? @@ -127,5 +129,5 @@ slug: birdnet-go-dev udev: true url: https://github.com/alexbelgium/hassio-addons usb: true -version: "20260929" +version: "20260929.1" video: true diff --git a/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf b/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf index 21fc2c9319..43eff1bdac 100644 --- a/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf +++ b/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf @@ -4,6 +4,10 @@ server { include /etc/nginx/includes/proxy_params.conf; location / { + # Only the Supervisor's ingress proxy may use this server. + allow 172.30.32.2; + deny all; + proxy_pass http://localhost:8080/; rewrite ^%%ingress_entry%%/?(.*)$ /$1 break;